BOOTWRECK is a custom destructive Master Boot Record wiper associated with APT38, a financially motivated cluster linked to the Lazarus Group and North Korean cyber operations. It is designed to render Windows systems inoperable by wiping the victim machine’s MBR and then initiating a reboot, preventing normal boot and disrupting recovery. BOOTWRECK has been referenced in reporting on destructive activity affecting Latin American financial organizations and fits the broader Lazarus/APT38 pattern of using disruptive malware in support of financially motivated intrusions, including operations against banks and other financial-sector targets. Its primary purpose is destructive impact rather than persistence or data theft, and its behavior is consistent with low-level disk corruption intended to disable compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New KillDisk Variant Hits Latin American Financial Organizations Again BOOTWRECK
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
3 distinct techniques documented for this family, organized by ATT&CK tactic.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
A custom MBR wiper used to render systems inoperable by overwriting the master boot record.
Wiper malware/variant discussed in attacks against Latin American financial organizations and in APT38 reporting.
Custom MBR-wiping malware that wipes the master boot record and then reboots the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.